Depth 28.1 · Security and compliance readiness · Level 3
NIS2 and DORA readiness
NIS2 and DORA readiness is preparation for two EU laws on cybersecurity and operational resilience. NIS2, Directive (EU) 2022/2555, sets security and incident reporting duties for medium and large organisations in sectors listed in the Directive, such as energy, transport, health and digital infrastructure. DORA, Regulation (EU) 2022/2554, sets rules on managing technology risk for financial entities in the EU and for some of their technology suppliers. UK organisations fall under the UK NIS Regulations 2018 and the ICO regime instead, so which set applies depends on where you operate. Whether any of them applies to your company is a legal question for your counsel; our work is preparation, not legal advice.
Specification
- Input
- Your counsel's view on which law applies, current security policies, system and supplier inventories, and incident procedures.
- Method
- We break the relevant text into individual requirements, map each to the systems and teams involved, record whether a working control exists, and note the evidence that shows it.
- Deliverable
- Control gap register: every requirement, the control that meets it or the gap where none does, the evidence and an owner.
- Measured by
- Requirements with a working control and current evidence, and gaps closed against their planned dates.
Most often bought inPayments and fintech, Logistics and supply chain
The artefact, before and after
Control gap register: every requirement, the control that meets it or the gap where none does, the evidence and an owner.
Inside it
- 01Requirement breakdown from Directive (EU) 2022/2555 or Regulation (EU) 2022/2554
- 02Mapping to systems and teams
- 03Incident handling and reporting procedures
- 04Supplier and third party risk review
- 05Gap register with owners
Typical first engagement
The usual order of a first piece of work. Timing and price are set at scoping, once we have seen the stack.
- 01Scope with counselYou get: Your counsel's view on which law applies, recorded as the starting point.
- 02Requirement registerYou get: Each relevant requirement listed in plain language.
- 03Gap registerYou get: Each requirement mapped to a control, an owner, evidence and a status.
- 04Remediation planYou get: Open gaps ordered by risk, as preparation only and not certification.
Security and compliance readiness
Next in this line
Ask about this part of the stack
Write one question about NIS2 and DORA readiness in your own systems. We answer it in writing and name what we would need to see to answer it properly.
A written reply, no call needed.